|
|
|
|
|
by eliseumds
2360 days ago
|
|
Thanks for pointing out the `<!--` vulnerability. In regards to rendering the string inside a JSON.parse, we do that because of performance: https://v8.dev/blog/cost-of-javascript-2019. From what I remember, we had some issues with IE11, thus the replacement for the other characters. We'll consider "application/json", makes sense. |
|